|
1 | | -items: |
2 | | -- name: Microsoft Defender for Identity Documentation |
3 | | - href: index.yml |
4 | | -- name: Overview |
5 | | - items: |
6 | | - - name: Welcome to Defender for Identity |
7 | | - href: what-is.md |
8 | | - - name: What's new? |
9 | | - href: whats-new.md |
10 | | - - name: Deploy and monitor for Zero Trust |
11 | | - href: zero-trust.md |
12 | | - - name: System architecture |
13 | | - href: architecture.md |
14 | | - - name: Defender for Identity in the Microsoft Defender portal |
15 | | - href: microsoft-365-security-center-mdi.md |
16 | | - - name: Defender for Identity for US Government |
17 | | - href: us-govt-gcc-high.md |
18 | | -- name: Deploy |
19 | | - expanded: true |
20 | | - items: |
21 | | - - name: Quick installation guide |
22 | | - href: deploy/quick-installation-guide.md |
23 | | - - name: Pilot and deploy Microsoft Defender XDR |
24 | | - href: /defender-xdr/pilot-deploy-overview?toc=/defender-for-identity/toc.json&bc=/defender-for-identity/breadcrumb/toc.json |
25 | | - - name: Defender for Identity deployment overview |
26 | | - href: deploy/deploy-defender-identity.md |
27 | | - - name: Plan and prepare |
28 | | - items: |
29 | | - - name: Defender for Identity prerequisites |
30 | | - href: deploy/prerequisites.md |
31 | | - - name: Plan your Defender for Identity capacity |
32 | | - href: deploy/capacity-planning.md |
33 | | - - name: Deploy Defender for Identity |
34 | | - items: |
35 | | - - name: Configure connectivity settings |
36 | | - href: deploy/configure-proxy.md |
37 | | - displayName: proxy |
38 | | - - name: Test connectivity settings |
39 | | - href: deploy/test-connectivity.md |
40 | | - - name: Download the Defender for Identity sensor |
41 | | - href: deploy/download-sensor.md |
42 | | - - name: Install the Defender for Identity sensor |
43 | | - href: deploy/install-sensor.md |
44 | | - - name: Configure the Defender for Identity sensor |
45 | | - href: deploy/configure-sensor-settings.md |
46 | | - - name: Post-deployment configuration |
47 | | - items: |
48 | | - - name: Configure event collection |
49 | | - items: |
50 | | - - name: Event collection overview |
51 | | - href: deploy/event-collection-overview.md |
52 | | - - name: Configure audit policies for Windows event logs |
53 | | - href: deploy/configure-windows-event-collection.md |
54 | | - - name: Roles and permissions |
55 | | - href: role-groups.md |
56 | | - - name: Configure a Directory Service account |
57 | | - items: |
58 | | - - name: Overview |
59 | | - href: deploy/directory-service-accounts.md |
60 | | - displayName: Directory Service Account, DSA |
61 | | - - name: Configure a DSA with a gMSA |
62 | | - href: deploy/create-directory-service-account-gmsa.md |
63 | | - - name: Configure remote calls to SAM |
64 | | - href: deploy/remote-calls-sam.md |
65 | | - - name: Extra deployment scenarios |
66 | | - items: |
67 | | - - name: Install on Microsoft AD FS / AD CS / Entra Connect servers |
68 | | - href: deploy/active-directory-federation-services.md |
69 | | - - name: Configure action accounts |
70 | | - href: deploy/manage-action-accounts.md |
71 | | - - name: Deploy for multiple Active Directory forests |
72 | | - href: deploy/multi-forest.md |
73 | | - - name: Configure a standalone sensor |
74 | | - items: |
75 | | - - name: Prerequisites for a standalone sensor |
76 | | - href: deploy/prerequisites-standalone.md |
77 | | - - name: Configure port mirroring |
78 | | - href: deploy/configure-port-mirroring.md |
79 | | - displayName: standalone |
80 | | - - name: Configure Windows Event Forwarding |
81 | | - href: deploy/configure-event-forwarding.md |
82 | | - displayName: standalone |
83 | | - - name: Listen for SIEM events |
84 | | - href: deploy/configure-event-collection.md |
85 | | - displayName: standalone |
86 | | - - name: Activate Defender for Identity capabilities on your domain controller |
87 | | - href: deploy/activate-capabilities.md |
88 | | -- name: Manage |
89 | | - items: |
90 | | - - name: View the ITDR dashboard |
91 | | - href: dashboard.md |
92 | | - - name: View and manage health issues |
93 | | - href: health-alerts.md |
94 | | - - name: Defender for Identity reports |
95 | | - href: reports.md |
96 | | - - name: Settings |
97 | | - items: |
98 | | - - name: About page |
99 | | - href: settings-about.md |
100 | | - - name: Manage and update sensors |
101 | | - href: sensor-settings.md |
102 | | - - name: Uninstall a sensor |
103 | | - href: uninstall-sensor.md |
104 | | - - name: VPN integration |
105 | | - href: vpn-integration.md |
106 | | - - name: Set entity tags |
107 | | - href: entity-tags.md |
108 | | - - name: Configure detection exclusions |
109 | | - href: exclusions.md |
110 | | - - name: Automated response exclusions |
111 | | - href: automated-response-exclusions.md |
112 | | - - name: Email and syslog notifications |
113 | | - href: notifications.md |
114 | | - - name: Adjust alert thresholds |
115 | | - href: advanced-settings.md |
116 | | - displayName: advanced settings |
117 | | - - name: Troubleshooting |
118 | | - items: |
119 | | - - name: Troubleshooting known issues |
120 | | - href: troubleshooting-known-issues.md |
121 | | - - name: Troubleshoot using logs |
122 | | - href: troubleshooting-using-logs.md |
123 | | -- name: Investigate and respond |
124 | | - items: |
125 | | - - name: Assets |
126 | | - items: |
127 | | - - name: Identity inventory |
128 | | - href: identity-inventory.md |
129 | | - - name: Investigate assets |
130 | | - href: investigate-assets.md |
131 | | - - name: Lateral movement paths |
132 | | - items: |
133 | | - - name: Understand and investigate lateral movement paths |
134 | | - href: understand-lateral-movement-paths.md |
135 | | - - name: Alerts |
136 | | - items: |
137 | | - - name: Alerts overview |
138 | | - href: alerts-overview.md |
139 | | - - name: Understanding security alerts |
140 | | - href: understanding-security-alerts.md |
141 | | - - name: Investigate security alerts |
142 | | - href: manage-security-alerts.md |
143 | | - - name: Monitored activities |
144 | | - href: monitored-activities.md |
145 | | - - name: Understanding Network Name Resolution (NNR) |
146 | | - href: nnr-policy.md |
147 | | - - name: Reconnaissance and discovery alerts |
148 | | - href: reconnaissance-discovery-alerts.md |
149 | | - - name: Persistence and privilege escalation alerts |
150 | | - href: persistence-privilege-escalation-alerts.md |
151 | | - - name: Credential access alerts |
152 | | - href: credential-access-alerts.md |
153 | | - - name: Lateral movement alerts |
154 | | - href: lateral-movement-alerts.md |
155 | | - - name: Other alerts |
156 | | - href: other-alerts.md |
157 | | - - name: Remediation |
158 | | - items: |
159 | | - - name: Remediation actions |
160 | | - href: remediation-actions.md |
161 | | - - name: Security posture |
162 | | - items: |
163 | | - - name: Overview |
164 | | - href: security-assessment.md |
165 | | - - name: Hybrid security |
166 | | - items: |
167 | | - - name: Change password for Microsoft Entra seamless SSO account |
168 | | - href: change-password-microsoft-entra-seamless-single-sign-on.md |
169 | | - displayName: Microsoft Entra connect |
170 | | - - name: Rotate password for Microsoft Entra Connect connector account |
171 | | - href: rotate-password-microsoft-entra-connect.md |
172 | | - displayName: Microsoft Entra Connect |
173 | | - - name: Remove unnecessary replication permissions for Microsoft Entra Connect connector account |
174 | | - href: remove-replication-permissions-microsoft-entra-connect.md |
175 | | - - name: Identity infrastructure |
176 | | - items: |
177 | | - - name: Built-in Active Directory Guest account is enabled |
178 | | - href: built-in-active-directory-guest-account-is-enabled.md |
179 | | - - name: Change Domain Controller computer account old password |
180 | | - href: domain-controller-account-password-change.md |
181 | | - - name: Domain controllers with Print spooler service available assessment |
182 | | - href: security-assessment-print-spooler.md |
183 | | - - name: Remove local admins on identity assets |
184 | | - href: security-assessment-remove-local-admins.md |
185 | | - - name: Unmonitored domain controllers |
186 | | - href: security-assessment-unmonitored-domain-controller.md |
187 | | - - name: Unsecure domain configurations |
188 | | - href: security-assessment-unsecure-domain-configurations.md |
189 | | - - name: Certificates |
190 | | - items: |
191 | | - - name: Enforce encryption for RPC certificate enrollment interface (ESC8) |
192 | | - href: security-assessment-enforce-encryption-rpc.md |
193 | | - - name: Insecure ADCS certificate enrollment IIS endpoints (ESC8) |
194 | | - href: security-assessment-insecure-adcs-certificate-enrollment.md |
195 | | - - name: Misconfigured certificate templates owner (ESC4) |
196 | | - href: security-assessment-edit-misconfigured-owner.md |
197 | | - - name: Misconfigured Certificate Authority ACL (ESC7) |
198 | | - href: security-assessment-edit-misconfigured-ca-acl.md |
199 | | - - name: Misconfigured certificate templates ACL (ESC4) |
200 | | - href: security-assessment-edit-misconfigured-acl.md |
201 | | - - name: Misconfigured enrollment agent certificate template (ESC3) |
202 | | - href: security-assessment-edit-misconfigured-enrollment-agent.md |
203 | | - - name: Overly permissive certificate template with privileged EKU (ESC2) |
204 | | - href: security-assessment-edit-overly-permissive-template.md |
205 | | - - name: Prevent Certificate Enrollment with arbitrary Application Policies (ESC15) |
206 | | - href: prevent-certificate-enrollment-esc15.md |
207 | | - - name: Prevent requests for certificates valid for arbitrary users (ESC1) |
208 | | - href: security-assessment-prevent-users-request-certificate.md |
209 | | - - name: Vulnerable Certificate Authority setting (ESC6) |
210 | | - href: security-assessment-edit-vulnerable-ca-setting.md |
211 | | - - name: Group policy |
212 | | - items: |
213 | | - - name: GPO assigns unprivileged identities to local groups with elevated privileges |
214 | | - href: gpo-assigns-unprivileged-identities.md |
215 | | - - name: GPO can be modified by unprivileged accounts |
216 | | - href: modified-unprivileged-accounts-gpo.md |
217 | | - - name: Reversible passwords found in GPOs |
218 | | - href: reversible-passwords-group-policy.md |
219 | | - - name: Accounts |
220 | | - items: |
221 | | - - name: Accounts with non-default Primary Group ID |
222 | | - href: accounts-with-non-default-pgid.md |
223 | | - - name: Admin SDHolder permissions |
224 | | - href: security-assessment-remove-suspicious-access-rights.md |
225 | | - - name: Change password for krbtgt account |
226 | | - href: change-password-krbtgt-account.md |
227 | | - - name: Change password of built-in domain Administrator account |
228 | | - href: change-password-domain-administrator-account.md |
229 | | - - name: Dormant entities in sensitive groups assessment |
230 | | - href: security-assessment-dormant-entities.md |
231 | | - - name: DCSync permissions |
232 | | - href: security-assessment-non-admin-accounts-dcsync.md |
233 | | - - name: Ensure privileged accounts are not delegated |
234 | | - href: ensure-privileged-accounts-with-sensitive-flag.md |
235 | | - - name: Entities exposing credentials in clear text assessment |
236 | | - href: security-assessment-clear-text.md |
237 | | - - name: LAPS usage assessment |
238 | | - href: security-assessment-laps.md |
239 | | - - name: Riskiest lateral movement paths |
240 | | - href: security-assessment-riskiest-lmp.md |
241 | | - - name: Unsecure Kerberos delegation assessment |
242 | | - href: security-assessment-unconstrained-kerberos.md |
243 | | - - name: Unsecure SID History attributes |
244 | | - href: security-assessment-unsecure-sid-history-attribute.md |
245 | | - - name: Unsecure account attributes |
246 | | - href: security-assessment-unsecure-account-attributes.md |
247 | | - - name: Weak cipher usage assessment |
248 | | - href: security-assessment-weak-cipher.md |
249 | | -- name: Reference |
250 | | - items: |
251 | | - - name: Operations guide |
252 | | - items: |
253 | | - - name: Overview |
254 | | - displayName: operations guide |
255 | | - href: ops-guide/ops-guide.md |
256 | | - - name: Daily activities |
257 | | - href: ops-guide/ops-guide-daily.md |
258 | | - - name: Weekly activities |
259 | | - href: ops-guide/ops-guide-weekly.md |
260 | | - - name: Monthly activities |
261 | | - href: ops-guide/ops-guide-monthly.md |
262 | | - - name: Quarterly / Ad-hoc activities |
263 | | - href: ops-guide/ops-guide-quarterly.md |
264 | | - - name: Frequently asked questions |
265 | | - href: technical-faq.yml |
266 | | - - name: SIEM log reference |
267 | | - href: cef-format-sa.md |
268 | | - - name: PowerShell |
269 | | - href: /powershell/defenderforidentity/overview-defenderforidentity |
270 | | - - name: Support |
271 | | - href: support.md |
272 | | - - name: Defender for Identity data security and privacy |
273 | | - href: privacy-compliance.md |
274 | | - - name: Security baseline |
275 | | - href: /security/benchmark/azure/baselines/defender-for-identity-security-baseline?toc=/defender-for-identity/toc.json |
276 | | - - name: What's new archive |
277 | | - href: whats-new-archive.md |
278 | | - - name: Migrate from Advanced Threat Analytics (ATA) |
279 | | - href: migrate-from-ata-overview.md |
280 | | -- name: Microsoft Defender XDR Docs |
281 | | - items: |
282 | | - - name: Microsoft Defender XDR |
283 | | - href: /microsoft-365/security/defender/ |
284 | | - - name: Microsoft Defender for Office 365 |
285 | | - href: /microsoft-365/security/office-365-security/ |
286 | | - - name: Microsoft Defender for Endpoint |
287 | | - href: /microsoft-365/security/defender-endpoint/ |
288 | | - - name: Microsoft Defender for Cloud Apps |
289 | | - href: /cloud-app-security/ |
290 | | - - name: Microsoft Defender Vulnerability Management |
291 | | - href: /microsoft-365/security/defender-vulnerability-management/ |
| 1 | +- name: Replace Enterprise or Domain Admin account for Entra Connect AD DS |
| 2 | + Connector account |
| 3 | + href: replace-entra-connect-default-admin.md |
| 4 | + displayName: MDI |
0 commit comments